oras-project oras-go

2 known vulnerabilities in oras-project oras-go, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-85732 CVSS 4.7 medium oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, the parseLink function in registry/remote/utils.go accepts an absolute…
  • CVE-2026-85731 CVSS 8.8 high oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, content/file.Store extraction of OCI layers marked with…